IBM Verify

IBM Verify

Join this online user group to communicate across Security product users and IBM experts by sharing advice and best practices with peers and staying up to date regarding product enhancements.

 View Only
  • 1.  LDAP Verify Directory unauthenticated search

    Posted Wed March 05, 2025 09:36 AM

    Hi,

    i have a Verify Directory 10.0.1 (the old SDS) server which can be interrogated without authentication.

    A simple ldapsearch without a username/password retrieve the data.

    I usually login as cn=root to perform write operation but i'd like the read operation to be authenticated too and block unauthenticated ldapsearch.

    Do you know how to do it? Using the "IBM Security Directory Server Web Administration Tool" i can't find any option about it.

    Thank you,

    S.



  • 2.  RE: LDAP Verify Directory unauthenticated search
    Best Answer

    Posted Thu March 06, 2025 03:03 AM

    I think this is what you are looking for :

    The anonymous access can also be changed in your ibmslapd.conf altering the ibm-slapdAllowAnon: TRUE  in the dn: cn=Connection Management, cn=Front End, cn=Configuration section

    HTH



    ------------------------------
    Franz Wolfhagen
    WW IAM Solution Architect - Certified Consulting IT Specialist
    IBM Expert Labs
    ------------------------------



  • 3.  RE: LDAP Verify Directory unauthenticated search

    Posted Thu March 06, 2025 05:08 AM

    Thank you, that was exactly what i was looking for.